A data leakage behavior identification and hierarchical blocking method based on deep learning
Patent Information
- Application Number
- CN202610545928.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-23
- Publication Date
- 2026-09-01
AI Technical Summary
此类方法通常侧重于对单条事件记录进行检测,或者仅针对外发结果本身进行拦截判定,虽然能够在一定程度上识别明显异常的外发行为,但对于由多源事件共同构成的连续行为过程缺乏有效的关联分析能力
本发明围绕受控信息环境中的原始行为数据采集、待处理事件流构建、用户行为序列生成、对象语义表征提取、完整行为操作链构建、多关系证据图建模、改进Graphormer模型关联推理以及阻断等级生成,形成了从数据渗漏线索发现到风险处置输出的连续处理机制。相较于现有技术中仅针对单条事件记录、单次外发结果或静态规则进行判断的方式,本发明能够将终端侧、传输侧和服务侧形成的原始行为数据进行统一汇聚,并通过时间统一、来源对齐和重复折叠处理,将分散、异源且冗余的事件记录转换为具有连续性的用户行为序列,从而提高对用户真实操作过程的还原能力。通过对数据对象执行逐层内容展开和结构拆分处理,本发明能够从不同封装结构中提取可比较的内容单元,并进一步汇合形成对象语义表征,使数据对象不再仅以表面形式参与分析,而是以具有内部结构关系的语义结果参与后续推理。
Smart Images

Figure CN122674033A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security management technology, and in particular to a method for identifying and hierarchically blocking data leakage behavior based on deep learning. Background Technology
[0002] With the increasing frequency of data flow in government and enterprise intranets, industry private networks, terminal office systems, and business collaboration platforms, the security risks associated with data access, processing, transfer, and outward transmission are constantly increasing. Especially in controlled information environments, the behavioral chains formed by users around data objects are more complex. Anomalies at a single moment, location, or object often fail to fully reflect the true data leakage process. Therefore, identifying continuous operational processes related to the current outward action from raw user behavior data and further assessing their risk level has become an important research direction in the field of data security protection.
[0003] In existing technologies, most solutions for data leakage prevention rely on terminal auditing, transmission monitoring, rule matching, or static policy control. These methods typically focus on detecting single event records or intercepting outgoing results only. While they can identify obviously abnormal outgoing behaviors to some extent, they lack effective correlation analysis capabilities for continuous behavioral processes composed of multiple sources of events. In particular, when the same user continuously processes content, connects behaviors, and navigates paths around the same data object, existing technologies struggle to organize scattered records into a complete chain of behavioral operations and further establish the correspondence between the semantic representation of the object and the representation of the behavioral chain.
[0004] Furthermore, existing technologies typically lack deep association reasoning mechanisms for multi-relationship evidence graphs, failing to uniformly model the subject-based, object-based, and path-based relationships between users, data objects, behavioral fragments, and external targets. This results in data leakage analysis remaining at the level of isolated event judgment. Even when some solutions incorporate machine learning models, they mostly focus on shallow classification processing, lacking reasoning capabilities based on graph structure propagation. Consequently, it is difficult to further generate discriminative blocking levels from graph association reasoning results.
[0005] Therefore, how to provide a deep learning-based method for identifying and hierarchically blocking data leakage behavior is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0006] One objective of this invention is to propose a deep learning-based method for identifying and hierarchically blocking data leakage behavior. This invention achieves more complete identification of data leakage processes related to the current outgoing action by uniformly aggregating, reconstructing sequences, extracting object semantic representations, and constructing behavioral operation chains from raw behavioral data. It also combines multi-relational evidence graphs with association reasoning from an improved Graphormer model. Based on the distance between inference node vectors, it generates corresponding blocking levels, thereby achieving accurate identification and hierarchical blocking of data leakage behavior.
[0007] A method for identifying and hierarchically blocking data leakage behavior based on deep learning according to an embodiment of the present invention includes the following steps: Step 1: Collect raw behavioral data of users in a controlled information environment and generate corresponding processing event streams; Step 2: Perform time unification, source alignment, and repetitive folding on the event stream to be processed, convert it into unified behavior fragments, and generate user behavior sequences according to the order of occurrence; Step 3: Perform content expansion and structural decomposition on each data object in the user behavior sequence to obtain the semantic representation of the object; Step 4: Based on the sequential relationship in the user behavior sequence, continuously splice adjacent behavior segments to construct a complete behavior operation chain corresponding to the current outgoing action; Step 5: Construct a multi-relationship evidence graph by combining the semantic representation of the object with the behavioral chain representation according to the subject association, object association, and path association; Step 6: Input the multi-relation evidence graph into the improved Graphormer model, and perform association reasoning through the graph precoding module, relation injection module, and graph propagation reasoning module to obtain the graph association reasoning result; Step 7: Calculate the Euclidean distance between different inference node vectors in the graph association inference results to generate the blocking level of the current outgoing action.
[0008] Optionally, step one specifically includes: In a controlled information environment, on the terminal side, transmission side, and service side, user identity identifier, session identifier, and object identifier are used as association primary keys. When a new behavior is detected, the original behavioral data between the user and the data object is collected. The raw behavioral data includes user behavior records, object state records, session association records, environment context records, and path flow records; A unified source tag and a local time sequence tag are attached to the raw event data. The raw event data generated by the same user within a continuous time window are merged according to the associated primary key and written into the buffer queue in the order of event arrival to form a stream of events to be processed.
[0009] Optionally, step two specifically involves: Extract the corresponding occurrence time of each event record in the event stream to be processed, and convert the event records generated at different collection locations to a unified time base to obtain a time-unified event set; Based on the source marker, associated primary key, and arrival location of each event record, source mapping and location registration are performed on the time-unified event set to establish a correspondence between heterogeneous event records describing the same behavioral process, thus obtaining the source alignment result; Based on the primary key of the source alignment results, the temporal adjacency relationship and the content pointing relationship, the event fragments that appear repeatedly and describe the same behavior process are merged and compressed to form a unified set of behavior fragments after redundancy removal. The unified set of behavioral segments is arranged sequentially according to a unified time base, and corresponding user behavior sequences are generated with users as the organizational unit.
[0010] Optionally, step three specifically includes: Extract data objects from the user behavior sequence based on object identifiers, and perform layer-by-layer expansion processing on each data object according to the content encapsulation relationship of each data object: When the data object has a single-layer content structure, its content is directly read and the original content unit is formed. When the data object has a multi-layer encapsulation structure, the outer encapsulation is removed in sequence, the inner content is extracted, and the correspondence between the outer content and the inner content is established until the original content unit set corresponding to each data object is obtained. The original content unit set is subjected to structural splitting processing, which involves dividing each original content unit according to its content boundaries to obtain multiple basic content fragments. Further structural localization is performed on each basic content fragment. The structural localization is to determine the hierarchical position, preceding and following position and belonging position of each basic content fragment in the corresponding data object, and to reorganize the basic content fragments with continuous positional relationships to obtain the fragment semantic vector. By merging the semantic vectors of fragments belonging to the same data object, we can obtain the object semantic representation of each data object.
[0011] Optionally, step four specifically includes: Locate the target behavior segment corresponding to the current outgoing action from the user behavior sequence, and use the target behavior segment as the backtracking endpoint to extract candidate behavior segments adjacent to the target behavior segment along the time backward direction of the user behavior sequence. Based on the time interval between the candidate behavior segment and the target behavior segment, candidate behavior segments with a time interval greater than a preset interval threshold are determined to belong to the same continuous behavior process as the target behavior segment; Candidate behavior segments belonging to the same continuous behavior process are sequentially incorporated before the target behavior segment to form an initial behavior operation chain; Using the merged first behavior segment as the new backtracking connection point, the extraction and judgment process is repeated until there are no candidate behavior segments that meet the continuous splicing conditions, at which point the backtracking stops, and a complete behavior operation chain corresponding to the current outgoing action is obtained.
[0012] Optionally, step five specifically includes: Extract the data object identifier corresponding to the semantic representation of the object and the user identifier, behavior fragment identifier, and outgoing target identifier corresponding to the behavior chain representation; User identifier, data object identifier, behavior fragment identifier, and outgoing target identifier are used as assembly indexes; based on the attribution relationship corresponding to the same user identifier, the semantic representation of the object formed by the same user and the behavior chain representation are linked to establish subject association relationship; Based on the pointing relationship corresponding to the same data object identifier, the semantic representation of the object representing the same data object and the behavioral chain representation are linked to establish the object association relationship; Based on the connection results and final direction results of each behavior segment in the behavior chain representation, the preceding behavior segments, corresponding data objects and outgoing targets connected with the current outgoing action are linked together to establish path association relationships; After completing the connection of subject relationships, object relationships, and path relationships, a multi-relationship evidence graph is generated, using the semantic representation of each object and the representation of each behavioral chain as graph node representations, and the subject relationships, object relationships, and path relationships as graph edge representations.
[0013] Optionally, the improved Graphormer model is specifically: The multi-relation evidence graph is input into the graph precoding module. The node representations corresponding to each node are read in the order of node number, and the edge representations corresponding to each edge are read in the order of edge connection. Each node representation is mapped to an initial node vector, and each edge representation is mapped to an initial edge vector. Based on the connection positions of each node in the multi-relation evidence graph, a node adjacency list is established to generate the initial graph encoding result; The initial graph encoding result is input into the relation injection module. Based on the order of each edge in the action operation chain, the corresponding temporal bias value is calculated and written into the corresponding initial node vector and initial edge vector to obtain the temporal injection result. The temporal bias value is calculated as follows: For the preceding and following action segments in the action operation chain, let the sequential position of the preceding action segment in the action operation chain be the preceding position, the sequential position of the following action segment in the action operation chain be the following position, the occurrence time of the preceding action segment be the preceding time, and the occurrence time of the following action segment be the following time. Subtracting the preceding position from the subsequent position yields the sequence distance; subtracting the preceding time from the subsequent time yields the time distance; and dividing the sequence distance by the time distance yields the timing offset value. The temporal injection results are input into the graph propagation inference module. Taking each node in the temporal injection results as the center node, the vectors of the adjacent nodes and the corresponding edge vectors directly connected to the center node are read. Calculate the Euclidean distance between adjacent node vectors and their corresponding edge vectors, and generate the associated response values for each adjacent direction; The vectors of each adjacent node are weighted according to the associated response values to generate a single-layer propagation result corresponding to each central node; The single-layer propagation results of each central node are summed and updated with the current node vector of the current central node to obtain the updated inference node vector; Repeat the process according to the preset number of propagation layers until the calculation of all propagation layers is completed, and output the graph association reasoning results.
[0014] Optionally, step seven specifically includes: Locate the target inference node corresponding to the current outgoing action from the graph association inference results, and extract the vectors of each inference node directly associated with the target inference node to form a set of local inference node vectors; Calculate the Euclidean distance between any two different inference node vectors in the local inference node vector set to obtain the corresponding node distance value; Accumulate all the distance values between nodes to generate the total distance corresponding to the current outgoing action; The sum of the distances is compared step by step with a preset risk threshold range to generate different blocking levels.
[0015] The beneficial effects of this invention are: This invention revolves around the acquisition of raw behavioral data in a controlled information environment, the construction of event streams to be processed, the generation of user behavior sequences, the extraction of object semantic representations, the construction of complete behavioral operation chains, multi-relational evidence graph modeling, improved Graphormer model association reasoning, and the generation of blocking levels, forming a continuous processing mechanism from the discovery of data leakage clues to the output of risk disposal. Compared with the existing technology that only judges a single event record, a single outgoing result, or static rules, this invention can uniformly aggregate the raw behavioral data formed by the terminal side, the transmission side, and the service side, and transform the scattered, heterogeneous, and redundant event records into continuous user behavior sequences through time unification, source alignment, and repeated folding processing, thereby improving the ability to reconstruct the user's actual operation process. By performing layer-by-layer content expansion and structural decomposition processing on data objects, this invention can extract comparable content units from different encapsulation structures and further merge them to form object semantic representations, so that data objects no longer participate in analysis only in a superficial form, but participate in subsequent reasoning with semantic results that have internal structural relationships.
[0016] By continuously splicing adjacent behavioral fragments, this invention can construct a complete behavioral operation chain around the current outgoing action, effectively reflecting the connection process before the formation of the outgoing action, thus enabling data leakage identification to move beyond isolated action judgment. By constructing a multi-relationship evidence graph based on subject association, object association, and path association according to the semantic representation of the object and the behavioral chain representation, and then inputting it into an improved Graphormer model for graph precoding, relation injection, and graph propagation inference processing, this invention can comprehensively utilize node representation, edge representation, and temporal bias information in the behavioral operation chain within a unified graph structure, enhancing the ability to mine complex association clues. Finally, this invention generates a blocking level based on the sum of Euclidean distances between different inference node vectors in the graph association inference result, allowing the blocking result to be directly based on the structural differences between inference nodes. This enables a graded output that matches the risk level of the current outgoing action, resulting in more complete behavior reconstruction, deeper association analysis, more stable inference results, and more refined blocking control. Attached Figure Description
[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is an overall flowchart of a deep learning-based method for identifying and hierarchically blocking data leakage behavior proposed in this invention. Figure 2 This is a schematic diagram illustrating the steps of generating a multi-relationship evidence graph for a deep learning-based data leakage behavior identification and hierarchical blocking method proposed in this invention. Figure 3This is a flowchart of the improved Graphormer model processing procedure for a deep learning-based data leakage behavior identification and hierarchical blocking method proposed in this invention. Detailed Implementation
[0018] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0019] refer to Figures 1-3 A deep learning-based method for identifying and hierarchically blocking data leakage behavior includes the following steps: Step 1: Collect raw behavioral data of users in a controlled information environment and generate corresponding processing event streams; Step 2: Perform time unification, source alignment, and repetitive folding on the event stream to be processed, convert it into unified behavior fragments, and generate user behavior sequences according to the order of occurrence; Step 3: Perform content expansion and structural decomposition on each data object in the user behavior sequence to obtain the semantic representation of the object; Step 4: Based on the sequential relationship in the user behavior sequence, continuously splice adjacent behavior segments to construct a complete behavior operation chain corresponding to the current outgoing action; Step 5: Construct a multi-relationship evidence graph by combining the semantic representation of the object with the behavioral chain representation according to the subject association, object association, and path association; Step 6: Input the multi-relation evidence graph into the improved Graphormer model, and perform association reasoning through the graph precoding module, relation injection module, and graph propagation reasoning module to obtain the graph association reasoning result; Step 7: Calculate the Euclidean distance between different inference node vectors in the graph association inference results to generate the blocking level of the current outgoing action.
[0020] This step, by unifying and organizing discrete behavioral records in a controlled information environment into a sequence of user behaviors with sequential relationships, effectively enhances the continuous reconstruction capability of complex data leakage processes, avoiding the one-sided identification problem caused by judging based on only a single event or partial record in existing technologies. By expanding and structurally decomposing data objects, data content in different encapsulation states can be transformed into comparable object semantic representations, thereby enhancing the ability to characterize hidden data leakage clues. Furthermore, by combining the joint modeling method of complete behavioral operation chains and multi-relationship evidence graphs, the originally scattered correlation information between subjects, objects, and paths can be concentrated in a unified inference space, improving the depth of identification of abnormal outflow correlation relationships. After using the improved Graphormer model to perform correlation inference on the multi-relationship evidence graph, it is possible to more accurately extract structural difference information related to the current outflow action, and quantify the degree of risk by using the Euclidean distance between different inference node vectors, making the generation of blocking levels more targeted and hierarchical. Thus, this invention not only improves the accuracy and completeness of data leakage behavior identification, but also enhances the refinement and practical adaptability of blocking control.
[0021] In this embodiment, step one specifically includes: In a controlled information environment, on the terminal side, transmission side, and service side, user identity identifier, session identifier, and object identifier are used as association primary keys. When a new behavior is detected, the original behavioral data between the user and the data object is collected. The raw behavioral data includes user behavior records, object state records, session association records, environment context records, and path flow records; The user behavior record is the initial operation trace formed by the user on the data object; The object state record is an initial record related to the current form, change state, and carrier form of the processed object; The session association record is an initial record that reflects the association relationship between the same user, the same object, or the same continuous operation chain; The environmental context record is an initial record reflecting the terminal environment, operating environment, and channel environment when the behavior occurs; The path flow record is an initial trajectory record that reflects the data object during its generation, processing, transfer, and outward flow. A unified source tag and a local time sequence tag are attached to the raw event data. The raw event data generated by the same user within a continuous time window are merged according to the associated primary key and written into the buffer queue in the order of event arrival to form a stream of events to be processed.
[0022] This step simultaneously covers the terminal side, transmission side, and service side during the raw behavioral data collection phase. Using user identity, session identity, and object identity as unified association keys, it effectively connects initial records that were originally scattered across different locations and sources. This allows subsequent processing to move beyond relying on isolated event judgments and instead unfold from a unified perspective of the same user, the same object, and the same continuous operation chain, improving data integrity and consistency in data leakage identification from the source. By dividing raw behavioral data into user behavior records, object state records, session association records, environmental context records, and path flow records, it simultaneously preserves multi-dimensional clues such as the behavior itself, object changes, link relationships, and environmental conditions. This enables subsequent analysis not only to determine whether an anomaly has occurred but also to more accurately distinguish the associated background and flow path before the anomaly occurred. Furthermore, by attaching unified source and local time sequence markers to the raw event data and merging and sequentially writing it within a continuous time window, it effectively reduces data fragmentation, temporal disorder, and duplication issues under multi-source collection conditions, resulting in a more continuous, traceable, and computable stream of events to be processed. Therefore, this content can provide a stable data foundation for subsequent unified behavior fragment generation, user behavior sequence construction, and complete behavior operation chain identification, thereby improving the method's ability to reconstruct complex data leakage behavior and front-end perception capabilities.
[0023] In this embodiment, step two specifically includes: Extract the corresponding occurrence time of each event record in the event stream to be processed, and convert the event records generated at different collection locations to a unified time base to obtain a time-unified event set; Based on the source marker, associated primary key, and arrival location of each event record, source mapping and location registration are performed on the time-unified event set to establish a correspondence between heterogeneous event records describing the same behavioral process, thus obtaining the source alignment result; Based on the primary key of the source alignment results, the temporal adjacency relationship and the content pointing relationship, the event fragments that appear repeatedly and describe the same behavior process are merged and compressed to form a unified set of behavior fragments after redundancy removal. The unified set of behavioral segments is arranged sequentially according to a unified time base, and corresponding user behavior sequences are generated with users as the organizational unit.
[0024] This step, by converting the event records in the event stream to a unified time base, eliminates the chronological discrepancies caused by inconsistent recording times between different collection locations. This ensures that subsequent behavior analysis is based on a unified time coordinate, thereby improving the accuracy of continuous behavior identification. By combining source markers, associated primary keys, and arrival locations to perform source mapping and location registration, heterogeneous event records describing the same behavior process can be effectively matched, avoiding fragmentation of multi-source records and enhancing the ability to completely reconstruct a single behavior process. Furthermore, merging and compressing duplicate event fragments based on associated primary keys, temporal adjacency, and content orientation reduces the interference of redundant records on subsequent analysis results, lowers the risk of misjudgment caused by repeated accumulation in the event stream, and makes the resulting unified set of behavior fragments more compact and clear. On this basis, the fragments are arranged sequentially according to the unified time base, and user behavior sequences are generated by organizing users. This transforms the originally discrete event fragments into behavior trajectories with continuous logic, providing stable input for subsequent data object analysis, behavior operation chain construction, and multi-relationship evidence graph modeling. Therefore, this content can significantly improve the ability to integrate multi-source events, the ability to reconstruct behavioral processes, and the temporal consistency of subsequent leakage identification and processing.
[0025] In this embodiment, step three specifically includes: Extract data objects from the user behavior sequence based on object identifiers, and perform layer-by-layer expansion processing on each data object according to the content encapsulation relationship of each data object: When the data object has a single-layer content structure, its content is directly read and the original content unit is formed. When the data object has a multi-layer encapsulation structure, the outer encapsulation is removed in sequence, the inner content is extracted, and the correspondence between the outer content and the inner content is established until the original content unit set corresponding to each data object is obtained. The original content unit set is subjected to structural splitting processing, which involves dividing each original content unit according to its content boundaries to obtain multiple basic content fragments. Further structural localization is performed on each basic content fragment. The structural localization is to determine the hierarchical position, preceding and following position and belonging position of each basic content fragment in the corresponding data object, and to reorganize the basic content fragments with continuous positional relationships to obtain the fragment semantic vector. By merging the semantic vectors of fragments belonging to the same data object, we can obtain the object semantic representation of each data object.
[0026] This step establishes a unified content parsing path for data objects at different encapsulation levels. Through layer-by-layer unfolding, it restores data content that was originally difficult to compare directly due to the encapsulation form to analyzable original content units, thereby improving the ability to extract internal information from complex data objects. For multi-layer encapsulation structures, establishing a correspondence between outer and inner content helps maintain the hierarchical continuity and source consistency of data objects during the unfolding process, avoiding structural breaks or semantic disconnects after content parsing. By structurally splitting the original content unit set according to content boundaries, mixed content can be divided into finer-grained basic content fragments, allowing subsequent analysis to go beyond the overall object level and delve into the fragment level for identification and comparison. Further combining hierarchical position, preceding and following position, and belonging position for structural localization and continuous reorganization preserves the internal organizational relationships and preceding and following connections of data objects when generating fragment semantic vectors, so that the obtained representation not only contains content information but also reflects structural distribution characteristics. By combining the semantic vectors of fragments corresponding to the same data object, a more complete and stable semantic representation of the object can be formed, providing a consistent object input basis for subsequent behavioral chain association analysis and multi-relationship evidence graph construction, thereby enhancing the ability to identify and semantically characterize hidden leakage objects.
[0027] In this embodiment, step four specifically includes: Locate the target behavior segment corresponding to the current outgoing action from the user behavior sequence, and use the target behavior segment as the backtracking endpoint to extract candidate behavior segments adjacent to the target behavior segment along the time backward direction of the user behavior sequence. Based on the time interval between the candidate behavior segment and the target behavior segment, candidate behavior segments with a time interval greater than a preset interval threshold are determined to belong to the same continuous behavior process as the target behavior segment; Candidate behavior segments belonging to the same continuous behavior process are sequentially incorporated before the target behavior segment to form an initial behavior operation chain; Using the merged first behavior segment as the new backtracking connection point, the extraction and judgment process is repeated until there are no candidate behavior segments that meet the continuous splicing conditions, at which point the backtracking stops, and a complete behavior operation chain corresponding to the current outgoing action is obtained.
[0028] This step uses the current outgoing action as the backtracking endpoint to extract adjacent candidate behavior segments from the user behavior sequence. This allows for the establishment of a continuous preceding behavior tracing path around the final outgoing result, enabling data leakage identification to move beyond isolated judgments of a single outgoing moment and instead perform a holistic analysis of the continuous operational process preceding the outgoing action. By judging based on the time interval between candidate behavior segments and target behavior segments, behavior segments closely related to the current outgoing action can be filtered from the user behavior sequence, thereby improving the targeting of continuous behavior process identification and reducing interference caused by irrelevant segments. The selected candidate behavior segments are sequentially merged into the target behavior segment to form an initial behavior operation chain. The extraction and judgment process is then repeated, using the first behavior segment as a new backtracking connection point. This allows the behavior operation chain to gradually extend forward during the backtracking process until it completely covers the preceding behavior trajectory associated with the current outgoing action, thus enhancing the ability to reconstruct the formation path of the outgoing action. This approach more clearly reflects the continuous connections between users before data leakage, enabling subsequent behavioral chain representations to no longer rely solely on local fragment features but to be built upon a complete behavioral context. This provides more complete, continuous, and directional input information for constructing multi-relational evidence graphs and graph association reasoning. It helps improve the process identification capability, chain reconstruction capability, and accuracy in determining the source of leakage risks for complex data leakage behaviors.
[0029] In this embodiment, step five specifically includes: Extract the data object identifier corresponding to the semantic representation of the object and the user identifier, behavior fragment identifier, and outgoing target identifier corresponding to the behavior chain representation; User identifier, data object identifier, behavior fragment identifier, and outgoing target identifier are used as assembly indexes; based on the attribution relationship corresponding to the same user identifier, the semantic representation of the object formed by the same user and the behavior chain representation are linked to establish subject association relationship; Based on the pointing relationship corresponding to the same data object identifier, the semantic representation of the object representing the same data object and the behavioral chain representation are linked to establish the object association relationship; Based on the connection results and final direction results of each behavior segment in the behavior chain representation, the preceding behavior segments, corresponding data objects and outgoing targets connected with the current outgoing action are linked together to establish path association relationships; After completing the connection of subject relationships, object relationships, and path relationships, a multi-relationship evidence graph is generated, using the semantic representation of each object and the representation of each behavioral chain as graph node representations, and the subject relationships, object relationships, and path relationships as graph edge representations.
[0030] This step extracts data object identifiers, user identifiers, behavior fragment identifiers, and outgoing target identifiers from the object semantic representation and behavior chain representation, and uses these as a unified assembly index. This allows analysis results that were originally scattered on the object and behavior sides to be incorporated into the same relational framework, improving the correspondence efficiency and organizational consistency between different types of information. By establishing subject associations based on the same user identifier, the object semantic representation and behavior chain representation formed by the same user can be uniformly linked, enabling subsequent analysis to make continuous judgments around the same subject and avoiding the separation of object information and behavior information. By establishing object associations based on the same data object identifier, the participation of the same data object in different behavior fragments can be expressed in a coherent manner, thereby enhancing the ability to track data objects across fragments during the outgoing process.
[0031] By establishing path relationships by combining the preceding and following connections and the final destination of each behavioral segment in the behavioral chain representation, the preceding behavioral segments connected to the current outgoing action, the corresponding data objects, and the outgoing target can be organized into a complete associated path. This allows the outgoing action to be understood not as a single-point result, but as a continuous link with a source, process, and destination. Furthermore, after the subject association, object association, and path association are connected, a multi-relationship evidence graph is generated using object semantic representation and behavioral chain representation as graph node representations and various association relationships as graph edge representations. This enables the centralized mapping of multi-dimensional heterogeneous information into a unified graph structure space, enhancing the ability of subsequent graph association reasoning to handle complex relationships. This not only improves the joint expression ability of object information and behavioral information, but also enhances the overall characterization ability of the source, flow process, and target destination of outgoing actions, providing a structurally complete, relationally clear, and semantically consistent input foundation for subsequent improvements to the Graphormer model for high-quality association reasoning.
[0032] In this embodiment, the improved Graphormer model is specifically as follows: The multi-relation evidence graph is input into the graph precoding module. The node representations corresponding to each node are read in the order of node number, and the edge representations corresponding to each edge are read in the order of edge connection. Each node representation is mapped to an initial node vector, and each edge representation is mapped to an initial edge vector. Based on the connection positions of each node in the multi-relation evidence graph, a node adjacency list is established to generate the initial graph encoding result; The initial graph encoding result is input into the relation injection module. Based on the order of each edge in the action operation chain, the corresponding temporal bias value is calculated and written into the corresponding initial node vector and initial edge vector to obtain the temporal injection result. The temporal bias value is calculated as follows: For the preceding and following action segments in the action operation chain, let the sequential position of the preceding action segment in the action operation chain be the preceding position, the sequential position of the following action segment in the action operation chain be the following position, the occurrence time of the preceding action segment be the preceding time, and the occurrence time of the following action segment be the following time. Subtracting the preceding position from the subsequent position yields the sequence distance; subtracting the preceding time from the subsequent time yields the time distance; and dividing the sequence distance by the time distance yields the timing offset value. The temporal injection results are input into the graph propagation inference module. Taking each node in the temporal injection results as the center node, the vectors of the adjacent nodes and the corresponding edge vectors directly connected to the center node are read. Calculate the Euclidean distance between adjacent node vectors and their corresponding edge vectors, and generate the associated response values for each adjacent direction; The vectors of each adjacent node are weighted according to the associated response values to generate a single-layer propagation result corresponding to each central node; The single-layer propagation results of each central node are summed and updated with the current node vector of the current central node to obtain the updated inference node vector; Repeat the process according to the preset number of propagation layers until the calculation of all propagation layers is completed, and output the graph association reasoning results.
[0033] The improved Graphormer model proposed in this step shares similarities with the traditional Graphormer model in that both use graph-structured data as input, model around nodes, edges, and the connections between nodes, and mine the relationships between elements in the graph through graph representation learning. Both follow the basic technical path of "graph input—graph encoding—relationship propagation—result output," that is, first converting the node and edge information in the graph into computable vector forms, then completing the interactive propagation of information in the graph based on the connections between nodes, and finally obtaining a reasoning result that can represent the overall or local relational state of the graph. Structurally, the improved model in this step also retains the core idea of Graphormer for encoding and reasoning on graph data, still using node and edge representations as basic inputs, and using graph propagation computation to aggregate the relationships between nodes. Therefore, it is consistent with the traditional Graphormer model in its underlying modeling objectives. Especially when dealing with multi-relation evidence graphs, the improved model still emphasizes that the nodes in the graph are not isolated, but form a propagable and updatable overall structure through edge connections. This is consistent with the traditional Graphormer model's emphasis on topological relationships and node context relationships. Furthermore, the graph precoding module, relation injection module, and graph propagation reasoning module in this step are essentially still processing frameworks that encode and update node information, edge information, and connection relationships in the graph layer by layer. This indicates that the improved model has not deviated from the graph computation foundation upon which the traditional Graphormer model relies, but is an extension of its original graph association reasoning ideas and a targeted modification for specific application scenarios.
[0034] The difference lies in the fact that the improved Graphormer model in this step does not directly adopt the traditional Graphormer model's method of uniformly encoding general graph structures. Instead, it restructures the input content, relation injection method, and propagation computation logic in a task-oriented manner, specifically addressing the temporal, procedural, and outward-spreading correlations of multi-relational evidence graphs in data leakage behavior identification scenarios. Traditional Graphormer models typically focus on expressing the general relationships between nodes and edges in static graphs. However, the improved model in this step first uses a graph precoding module to read node representations and edge representations according to node numbering order and edge connection order, and establishes a node adjacency list, ensuring that the entire graph input process strictly corresponds to the subject, object, and path relationships in the multi-relational evidence graph. Furthermore, traditional Graphormer models typically enhance graph representation through preset structural biases or general graph position encoding. The improved model in this step introduces a temporal bias value directly corresponding to the behavioral operation chain in the relation injection module. This temporal bias value is not empirically assigned, but rather calculated using the preceding and following positions, preceding and following times to obtain the sequential and temporal distances, which are then divided by the temporal distance. This gives the edge relationships in the graph a clear behavioral sequence meaning. Simultaneously, in the graph propagation inference module, this step does not employ an abstract, general attention aggregation method. Instead, it directly uses each node as the central node, reads the vectors of adjacent nodes and their corresponding edge vectors, calculates the Euclidean distance between them as the association response value, and then weights the adjacent node vectors based on the association response value and sums them with the current vector of the central node to update the value. This forms a propagation inference mechanism that better suits the current data leakage link analysis needs. Therefore, this improved model does not simply replace the local parameters in traditional Graphormer, but rather establishes a graph association inference structure with a clear scenario-specific focus around multi-relational evidence graphs, behavioral operation chains, and temporal bias calculation methods.
[0035] The beneficial effect of the improvements lies in the fact that by introducing multi-relation evidence graphs into the continuous processing framework of graph precoding, relation injection, and graph propagation inference, the improved Graphormer model proposed in this step can better fit the graph structure characteristics of the "subject-object-path" multi-relationship intertwining in the data leakage behavior identification task, thereby enhancing the ability to model the associations of complex outward behaviors. In particular, by introducing a temporal bias value determined by both sequential distance and temporal distance in the relation injection module, nodes and edges carry the sequential connection information of the behavior operation chain before entering subsequent propagation calculations. This embeds the temporal logic originally scattered in the behavior sequence into the graph structure, enhancing the ability to express continuous behavior processes. Furthermore, the graph propagation inference module uses the Euclidean distance between adjacent node vectors and corresponding edge vectors to generate association response values, and then updates adjacent node vectors with weights based on the association response values. This allows the node update process to directly reflect the degree of structural difference between nodes and edges, thereby improving the sensitivity of the inference results to abnormal association changes. Compared to the traditional approach of uniformly propagating general graph relationships, this improvement allows the model to not only preserve the original connectivity features in the multi-relation evidence graph when processing the graph structure corresponding to the current outgoing action, but also to more accurately characterize the strength of the connections and the direction of association transmission between action segments. The final output graph association inference results more realistically reflect the local inference state related to the current outgoing action, providing a more stable input basis for subsequent generation of blocking levels based on the Euclidean distance of different inference node vectors. Therefore, it can improve the targeting of data leakage behavior identification, the precision of graph association analysis, and the reliability of blocking level classification.
[0036] In this embodiment, step seven specifically includes: Locate the target inference node corresponding to the current outgoing action from the graph association inference results, and extract the vectors of each inference node directly associated with the target inference node to form a set of local inference node vectors; Calculate the Euclidean distance between any two different inference node vectors in the local inference node vector set to obtain the corresponding node distance value; Accumulate all the distance values between nodes to generate the total distance corresponding to the current outgoing action; The sum of the distances is compared step by step with a preset risk threshold range to generate different blocking levels.
[0037] Example 1: To verify the feasibility of this invention in practice, it was applied to an integrated software R&D and customer delivery office park in a provincial capital city. This park includes an R&D office network, a testing support network, a document collaboration platform, an internal instant messaging platform, an email system, file transfer services, code hosting services, and a terminal peripheral access management system. More than 2,000 employees are involved in daily operations, covering various roles such as R&D, testing, implementation, pre-sales, operations and maintenance, and project management. A typical problem that has long existed in this scenario is that data leakage does not always manifest as a single direct outgoing transmission, but often involves a continuous process of retrieval, opening, content organization, packaging, renaming, relaying, and then re-sending. Traditional security systems rely more on single alarm records, fixed rules, or single transmission results for judgment. When users organize multiple small files separately and then send them all at once, or relay them between different terminals before sending, problems such as the inability to connect preceding actions, unstable risk level assessments, and overly lenient or excessive blocking actions can easily occur. In actual operation, normal business collaboration and abnormal outgoing events have certain similarities in terms of surface operation, and it is often difficult to accurately distinguish them by relying solely on a single point of event. This is also the core technical problem that this invention aims to solve.
[0038] After deploying this invention in the park, the system continuously collects raw behavioral data of users in a controlled information environment and writes the records formed by the terminal side, transmission side, and service side into the processing event stream. For continuous trajectories formed by the same user around the same data object, the system first completes time unification, source alignment, and repetition folding, and then generates a user behavior sequence that reflects the true sequence relationship. For data objects that are accessed or prepared for outgoing, the system does not only look at the file name or extension, but further expands its content structure, unifying single-layer content and multi-layer encapsulated content into original content units, and then performs structural decomposition and location positioning to form an object semantic representation. At the same time, the system will backtrack around the current outgoing action, splicing adjacent behavior segments into a complete behavior operation chain. In this way, whether there are intensive searches, continuous openings, centralized sorting, or rapid transfers before a certain outgoing action can be completely preserved. Subsequently, the system connects the object semantic representation and the behavior chain representation according to the subject association relationship, object association relationship, and path association relationship to form a multi-relationship evidence graph, and then inputs it into the improved Graphormer model for association reasoning. After the model outputs the graph association inference results, the system further calculates the Euclidean distance between different inference node vectors related to the current outgoing action, and generates the blocking level based on the interval where the total distance is located, thereby realizing the dynamic differentiation of prompts, restrictions and blocking strength.
[0039] To verify the effectiveness of this invention, a typical business area within the park was selected as the implementation target. This business area had 480 terminal devices and 367 participants, operating continuously for 12 working weeks, covering high-frequency office behaviors such as internal document collaboration, test package distribution, customer delivery document generation, screenshot exchange, email correspondence, and peripheral device usage. During the statistical period, the system collected a total of 12.86 million raw behavioral data entries. After time unification and source alignment, a set of 9.42 million events to be analyzed was formed. Further repetition and folding yielded 2.37 million unified behavioral fragments, which, after being organized by user, generated over 316,000 behavioral sequences. Regarding outbound related activities, the system extracted 487,000 data objects, of which single-layer content structure objects accounted for approximately 60%, and multi-layer encapsulated structure objects accounted for approximately 40%. After content expansion and structural decomposition, over 19.4 million basic content fragments were obtained, ultimately forming over 480,000 sets of object semantic representations. When backtracking outgoing actions, an average of 6.8 valid action segments can be pieced together from each outgoing action, with the longest complete action operation chain reaching 27 segments, which is significantly better than the traditional approach that can only make local judgments around a single transmission action.
[0040] During operation, this business area encountered several representative risk scenarios. For example, a delivery support staff member repeatedly searched multiple delivery directories within a short period, then centrally organized the relevant files, and prepared to send them to an external email address via compression and relay. Traditional rule systems, due to the dispersed nature of these actions, only triggered a medium-level alert for the last email sent. However, this invention, after forming a complete behavioral operation chain, identified obvious aggregation and organization traces in its preceding steps, and connected the user, related data objects, and the outgoing target as a high-risk path in the multi-relationship evidence graph. Ultimately, a high blocking level was generated before sending, successfully preventing the outgoing email. In another scenario, a tester sent a large number of screenshots to the project group at night via internal communication tools. Traditional systems, because the screenshot content could not establish a stable association with the original objects, only generated a low-level alert. This invention, by aggregating the semantic vectors of the expanded fragments of the data objects corresponding to the screenshots, and combining the continuous opening and rapid screenshot trajectories in the behavioral chain, determined that this behavior significantly deviated from the normal problem feedback pattern, ultimately raising the blocking level and triggering restrictive measures. Conversely, for normal cross-departmental collaborative document flow, although the present invention also detects the outgoing path, it only generates a reminder and does not cause unnecessary blocking because the preceding behavior chain is stable, the semantic representation of the object is consistent with the usage habits of the job, and the total distance of the inference nodes falls into the low-risk range. This shows that the present invention can not only improve the recognition ability, but also control the level of false blocking.
[0041] To further demonstrate the implementation effect, this invention is compared with the original solution in the park under the same scenario. The original solution uses a combination of "terminal audit rules + email keyword matching + fixed threshold blocking", while this invention uses the method described in the claims of this application. The two solutions obtained the following results within the same business area, the same data range, and the same operating cycle.
[0042] Table 1. Comparison of Data Leakage Behavior Identification and Tiered Blocking Effects As shown in Table 1, the improvement of this invention is not only reflected in the single recognition accuracy, but also extends to the entire chain from front-end acquisition, process reconstruction, graph reasoning, to final blocking. The original solution had significant shortcomings in terms of original event acquisition coverage, heterogeneous event alignment success rate, and behavior sequence completeness rate, leading to subsequent analysis often being based on incomplete input. This invention, by unifying the processing of event streams and user behavior sequence reconstruction, makes the behavior context more continuous, thus increasing the average backtracking length of the behavior chain before outgoing events from 2.1 segments to 6.8 segments, and improving the success rate of constructing complete behavior operation chains by more than 40 percentage points. This means that the system no longer just looks at "an outgoing event has occurred," but can more clearly understand "how the outgoing event was formed step by step." At the same time, this invention achieves a parsing success rate of over 80% for multi-layered encapsulated objects, making the semantic representation of objects more stable, thereby supporting a multi-relationship evidence graph construction success rate of over 90%. As a result, the final high-risk event recall rate, high-risk outgoing event blocking success rate, and blocking level consistency rate are all significantly improved, while the false positive rate and ordinary collaborative false blocking rate are significantly reduced, indicating that this invention enhances security without excessively sacrificing business continuity. This embodiment demonstrates that the present invention can construct a complete behavioral operation chain around the current outbound action in a real office environment, perform deep association reasoning by combining object semantic representation and multi-relational evidence graphs, and then output the blocking level based on the Euclidean distance between the reasoning node vectors. Compared with the prior art, the present invention provides more complete identification of complex data leakage behavior, more thorough integration of multi-source heterogeneous events, more timely interception of high-risk outbound actions, and less interference with normal business collaboration. It can effectively solve the practical problems of traditional solutions, such as difficulty in reconstructing continuous outbound processes, difficulty in accurate classification, and difficulty in balancing security and availability.
[0043] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for identifying and hierarchically blocking data leakage behavior based on deep learning, characterized in that, Includes the following steps: Step 1: Collect raw behavioral data of users in a controlled information environment and generate corresponding processing event streams; Step 2: Perform time unification, source alignment, and repetitive folding on the event stream to be processed, convert it into unified behavior fragments, and generate user behavior sequences according to the order of occurrence; Step 3: Perform content expansion and structural decomposition on each data object in the user behavior sequence to obtain the semantic representation of the object; Step 4: Based on the sequential relationship in the user behavior sequence, continuously splice adjacent behavior segments to construct a complete behavior operation chain corresponding to the current outgoing action; Step 5: Construct a multi-relationship evidence graph by combining the semantic representation of the object with the behavioral chain representation according to the subject association, object association, and path association; Step 6: Input the multi-relation evidence graph into the improved Graphormer model, and perform association reasoning through the graph precoding module, relation injection module, and graph propagation reasoning module to obtain the graph association reasoning result; Step 7: Calculate the Euclidean distance between different inference node vectors in the graph association inference results to generate the blocking level of the current outgoing action.
2. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step one specifically involves: In a controlled information environment, on the terminal side, transmission side, and service side, user identity identifier, session identifier, and object identifier are used as association primary keys. When a new behavior is detected, the original behavioral data between the user and the data object is collected. The raw behavioral data includes user behavior records, object state records, session association records, environment context records, and path flow records; A unified source tag and a local time sequence tag are attached to the raw event data. The raw event data generated by the same user within a continuous time window are merged according to the associated primary key and written into the buffer queue in the order of event arrival to form a stream of events to be processed.
3. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step two specifically involves: Extract the corresponding occurrence time of each event record in the event stream to be processed, and convert the event records generated at different collection locations to a unified time base to obtain a time-unified event set; Based on the source marker, associated primary key, and arrival location of each event record, source mapping and location registration are performed on the time-unified event set to establish a correspondence between heterogeneous event records describing the same behavioral process, thus obtaining the source alignment result; Based on the primary key of the source alignment results, the temporal adjacency relationship and the content pointing relationship, the event fragments that appear repeatedly and describe the same behavior process are merged and compressed to form a unified set of behavior fragments after redundancy removal. The unified set of behavioral segments is arranged sequentially according to a unified time base, and corresponding user behavior sequences are generated with users as the organizational unit.
4. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step three specifically involves: Extract data objects from the user behavior sequence based on object identifiers, and perform layer-by-layer expansion processing on each data object according to the content encapsulation relationship of each data object: When the data object has a single-layer content structure, its content is directly read and the original content unit is formed. When the data object has a multi-layer encapsulation structure, the outer encapsulation is removed in sequence, the inner content is extracted, and the correspondence between the outer content and the inner content is established until the original content unit set corresponding to each data object is obtained. The original content unit set is subjected to structural splitting processing, which involves dividing each original content unit according to its content boundaries to obtain multiple basic content fragments. Further structural localization is performed on each basic content fragment. The structural localization is to determine the hierarchical position, preceding and following position and belonging position of each basic content fragment in the corresponding data object, and to reorganize the basic content fragments with continuous positional relationships to obtain the fragment semantic vector. By merging the semantic vectors of fragments belonging to the same data object, we can obtain the object semantic representation of each data object.
5. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step four specifically involves: Locate the target behavior segment corresponding to the current outgoing action from the user behavior sequence, and use the target behavior segment as the backtracking endpoint to extract candidate behavior segments adjacent to the target behavior segment along the time backward direction of the user behavior sequence. Based on the time interval between the candidate behavior segment and the target behavior segment, candidate behavior segments with a time interval greater than a preset interval threshold are determined to belong to the same continuous behavior process as the target behavior segment; Candidate behavior segments belonging to the same continuous behavior process are sequentially incorporated before the target behavior segment to form an initial behavior operation chain; Using the merged first behavior segment as the new backtracking connection point, the extraction and judgment process is repeated until there are no candidate behavior segments that meet the continuous splicing conditions, at which point the backtracking stops, and a complete behavior operation chain corresponding to the current outgoing action is obtained.
6. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step five specifically involves: Extract the data object identifier corresponding to the semantic representation of the object and the user identifier, behavior fragment identifier, and outgoing target identifier corresponding to the behavior chain representation; User identifier, data object identifier, behavior fragment identifier, and outgoing target identifier are used as assembly indexes; based on the attribution relationship corresponding to the same user identifier, the semantic representation of the object formed by the same user and the behavior chain representation are linked to establish subject association relationship; Based on the pointing relationship corresponding to the same data object identifier, the semantic representation of the object representing the same data object and the behavioral chain representation are linked to establish the object association relationship; Based on the connection results and final direction results of each behavior segment in the behavior chain representation, the preceding behavior segments, corresponding data objects and outgoing targets connected with the current outgoing action are linked together to establish path association relationships; After completing the connection of subject relationships, object relationships, and path relationships, a multi-relationship evidence graph is generated, using the semantic representation of each object and the representation of each behavioral chain as graph node representations, and the subject relationships, object relationships, and path relationships as graph edge representations.
7. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, The improved Graphormer model is specifically as follows: The multi-relation evidence graph is input into the graph precoding module. The node representations corresponding to each node are read in the order of node number, and the edge representations corresponding to each edge are read in the order of edge connection. Each node representation is mapped to an initial node vector, and each edge representation is mapped to an initial edge vector. Based on the connection positions of each node in the multi-relation evidence graph, a node adjacency list is established to generate the initial graph encoding result; The initial graph encoding result is input into the relation injection module. Based on the order of each edge in the action operation chain, the corresponding temporal bias value is calculated and written into the corresponding initial node vector and initial edge vector to obtain the temporal injection result. The temporal bias value is calculated as follows: For the preceding and following action segments in the action operation chain, let the sequential position of the preceding action segment in the action operation chain be the preceding position, the sequential position of the following action segment in the action operation chain be the following position, the occurrence time of the preceding action segment be the preceding time, and the occurrence time of the following action segment be the following time. Subtracting the preceding position from the subsequent position yields the sequence distance; subtracting the preceding time from the subsequent time yields the time distance; and dividing the sequence distance by the time distance yields the timing offset value. The temporal injection results are input into the graph propagation inference module. Taking each node in the temporal injection results as the center node, the vectors of the adjacent nodes and the corresponding edge vectors directly connected to the center node are read. Calculate the Euclidean distance between adjacent node vectors and their corresponding edge vectors, and generate the associated response values for each adjacent direction; The vectors of each adjacent node are weighted according to the associated response values to generate a single-layer propagation result corresponding to each central node; The single-layer propagation results of each central node are summed and updated with the current node vector of the current central node to obtain the updated inference node vector; Repeat the process according to the preset number of propagation layers until the calculation of all propagation layers is completed, and output the graph association reasoning results.
8. The method for identifying and hierarchically blocking data leakage behavior based on deep learning according to claim 1, characterized in that, Step seven specifically involves: Locate the target inference node corresponding to the current outgoing action from the graph association inference results, and extract the vectors of each inference node directly associated with the target inference node to form a set of local inference node vectors; Calculate the Euclidean distance between any two different inference node vectors in the local inference node vector set to obtain the corresponding node distance value; Accumulate all the distance values between nodes to generate the total distance corresponding to the current outgoing action; The sum of the distances is compared step by step with a preset risk threshold range to generate different blocking levels.